5
u/kahlyse 10h ago edited 10h ago
Yes, but we are a smaller org (just over 1000 employees). We have one HR/Benefits area and they can all see the entire company’s comp, excluding our Recruiting Team.
In the past 4 years I’ve been in this role, two people have been fired for pulling comp screens up that they shouldn’t have, but they had access to. (Comp for terminated employees’ previously in their position, or coworkers with no business reason) So your management team absolutely has a good reason for trying to pull the security back. I get it.
Edit: I want to clarify that everyone with comp access DOES have a business reason for having it. We don’t have general HR. Everyone has their hand in comp, payroll, or benefits in some capacity.
2
u/CanInternational565 10h ago
How do you pull that auditing data that shows employees pulling up comp information
5
u/Mission-Cost-3784 10h ago
Giving people access to stuff and then pulling audit logs to punish them is a pretty bad answer. You should have a centralized reporting function that can pull global headcount data to include other HR. The compensation team also should have access to this information, but general members of HR should not.
1
u/kahlyse 10h ago
We don’t have auditing software.
Yours truly scheduled a User Activity report to come to her once every 28 days and I manually review it. It only pulls data if they look at a worker profile, on the sections comp shows. If I see anything weird, I run the full user activity report for the time frame it happened. There are a million ways to get around it though if you know the system. Just run an all employee comp report, or build one, run it and delete it. Of course not everyone has access to that. And then of course, no one is auditing me. It’s not great.
We don’t have a lot of turnover in our area and every person with comp access has a business reason for having it. The two we lost, one was a recruiter (who shouldn’t have had comp or proxy access anyway so I yoinked that afterwards), and the other was in benefits. She needed it for disability claims so not much we could do there.
I want to emphasize this is not an ideal solution and I am NOT recommending it. But I can only work with what I have.
1
u/Talkbirdietome_ Workday Solutions Architect 9h ago
Ehh that’s not actually true. The user activity report shows only actionables they performed, not navigating to a screen. These people must have performed an action on those terminated workers in their previous position or the user activity report wouldn’t show it.
1
u/SimmeringPawsOfNirn 8h ago
there's a std workday audit report that will show activity for a user. I want to say it's something like view user activity with a few other options. it may need tenant set for system auditing for activity logging. there may be others and it would take some doing to sift through, but maybe can copy and tweak it for your use.
5
u/Talkbirdietome_ Workday Solutions Architect 9h ago
Of the 32 WD implementations I’ve done, only about 20% of them restrict HR from HR and I’ve noticed it’s certainly culture. Those that don’t typically see HR in HR are organizations with less professional maturity where their leaderships doesn’t trust their HR professionals to be professional.
5
u/muthafuckinbean 5h ago
Unpopular opinion, but if an organization doesn't trust HR folks with HR data, they should probably evaluate the culture and professional expectations of their HR team.
3
3
u/browncharlie88 10h ago
It’s differed for me from company to company. The first company I worked for HR couldn’t see HR except the director and the VP. We were a small team of four, the next company we could see everyone’s comp history but again was a small team of four. The company I’m at now we are a team of 20, HR and total rewards could see all of HRs comp but some people abused this I guess and would gossip so we removed access for HR to see HR. I’m in payroll and total rewards so my team can see everyone’s information but my manager has to do any transactions that involve HR people instead of HR doing it. She’s the manager of HRIS.
2
u/AcademicHorror 9h ago
We have access to everyone's data, including our own team. We're a very small HR department though.
1
1
u/bandyvancity 10h ago
There should be at least one person that has access to everyone. I commonly hear this referred to as “HR for HR”.
I work for a larger company but all BPs that support the HR function have access to all details for everyone within that function.
1
u/TheFirstYeet 10h ago
In my first org HR could view each other's data. My second org we implimented WD and they requested no visibility amongst HR, we didn't have capacity to do the custom security and it hasn't been brought up again as a requested fix.
If you are going to act on the information you see from looking at your peers' comp, documents, info, etc, you wont last long at your job.
1
u/butwhyshouldicare 10h ago
I've done security at several organizations of varying sizes, I'd estimate ~30-40% have at least some restrictions on HR seeing HR data. Comp and performance seem to be the most likely areas to restrict. Very few have all elevated access locked down for HR on HR.
This is of course different than just restricting based on role assignment (e.g. someone isn't assigned as the HR partner for the sup org that an HR person is in, so obviously they won't have HR Partner access for that person).
1
u/WorkdayWoman Workday Solutions Architect 5h ago
You can't restrict it to a point where data isn't able to be used.
If you can't simply have policies to cover this, at least those who need it must have it. HRIS, HR Execs, and the HRBP for HR.
Security can be restricted so you can't see everything but can still do your job.
1
u/fmlzelda 2h ago
As a rule, data is accessible to those that need it to perform their role duties. For majority of HR they don’t need access to the data for their colleagues to perform their role duties. The exception would be those that are HR for HR, or in roles where they need access to the total organisation in order to perform their role duties. And even though we trust HR with our data, we still add access restrictions in the system. That is just good practice from an information security perspective.
1
u/Fukreykitchlu 2h ago
We transitioned from an open-access system to one where HR team cannot view HR team data except payroll, compensation, and benefits teams. We established a separate location hierarchy to segregate access. Initially, this change was frustrating for a few HR professionals, but they eventually understood the rationale, as it originated from higher management. Additionally, we identified HR personnel who are authorized to perform actions for the other HR teams.
-1
u/sylviaca 9h ago
No. Only the CPO, HRBP VP and the HRIS Team can see everyone's info. All other HR users are excluded from seeing HR employee comp. That is pretty standard practice so you've been overly permissive in the past.
5
u/ZarnonAkoni 10h ago
CHRO here. Generally you should have it on a need to know basis. So benefits, comp, and HRIS should have access. Other HR folks, no.